Identity authentication method, personal security kernel node, device, and medium
Abstract
The present disclosure provides an identity authentication method, a personal security kernel node, a device, and a medium. The personal security kernel node is part of an identity authentication system, the identity authentication system further comprising a relying party node and a user identity credential certifier node. The method includes: obtaining an identity authentication assurance level corresponding to a service provided by a relying party; determining, according to the identity authentication assurance level, a user identity credential used by a user for the service; transmitting the user identity credential to a user identity credential certifier node through a relying party node, so that the user identity credential certifier node performs user identity credential authentication; and performing the service with the relying party node. According to the embodiments of the present disclosure, security of user identity assets can be improved during identity authentication.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An identity authentication method, performed by a computer device acting as a personal security kernel node of an identity authentication system, the identity authentication system further comprising a relying party node, a service-level user identity credential certifier node and a legal user identity credential certifier node, the method comprising:
obtaining an identity authentication assurance level corresponding to a service provided by a relying party; determining, according to the identity authentication assurance level, a user identity credential used by a user for the service; in accordance with a determination that the user identity credential is a legal identity credential, transmitting the user identity credential to the legal user identity credential certifier node via the relying party node, wherein the legal user identity credential certifier node is configured to perform user identity credential authentication for the user for the service; in accordance with a determination that the user identity credential is a service-level user identity credential, transmitting the user identity credential to the service-level user identity credential certifier node via the relying party node, wherein the service-level user identity credential certifier node is configured to perform user identity credential authentication for the user for the service; and performing the service with the relying party node in response to reception of a receipt indicating that the user identity credential authentication succeeds from one of the legal user identity credential certifier node and the service-level user identity credential certifier node.
2 . The method according to claim 1 , wherein the identity authentication system further comprises a relying party qualification certifier node, and the method further comprises:
obtaining relying party qualification information; and transmitting the relying party qualification information to the relying party qualification certifier node, wherein the relying party qualification certifier node performs relying party qualification authentication; and the obtaining an identity authentication assurance level corresponding to a service provided by a relying party comprises: obtaining, in response to receiving a reply indicating that the relying party qualification authentication succeeds from the relying party qualification certifier node, the identity authentication assurance level corresponding to the service provided by the relying party.
3 . The method according to claim 1 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
presenting candidate user identity credentials that match the identity authentication assurance level and the service provided by the relying party; and receiving a candidate user identity credential selected by the user, and determining the candidate user identity credential selected by the user as the user identity credential used by the user for the service.
4 . The method according to claim 3 , wherein the identity authentication system further comprises a peer certifier node, and after the obtaining an identity authentication assurance level corresponding to a service provided by a relying party, the method further comprises:
presenting peer certifier identifiers that match the identity authentication assurance level and the service provided by the relying party; receiving a peer certifier identifier selected by the user, and using the selected peer certifier identifier as authorization of the user to a peer certifier corresponding to the peer certifier identifier; transmitting the peer certifier identifier selected by the user to the relying party node, so that the relying party node transmits a verification request to the peer certifier corresponding to the peer certifier identifier; and performing the service with the relying party node in a case that a receipt indicating successful peer authentication transmitted by the peer certifier through the relying party node is received.
5 . The method according to claim 2 , wherein before the obtaining relying party qualification information, the method further comprises:
generating a pair of public and private keys of the user for the user in response to received user information, storing the private key, and issuing the public key; and after the performing the service with the relying party node, the method further comprises: signing a service performance result with the private key of the user, and transmitting the service performance result and the signature together to the relying party node, so that the relying party node verifies the signature by using the public key of the user.
6 . The method according to claim 2 , wherein the relying party qualification certifier node comprises a relying party identity authenticator node;
the relying party qualification information comprises a relying party identity certificate and an identifier of a relying party identity authenticator node that issues the relying party identity certificate; and the transmitting the relying party qualification information to the relying party qualification certifier node, so that the relying party qualification certifier node performs relying party qualification authentication comprises: transmitting the relying party identity certificate to the relying party identity authenticator node corresponding to the identifier of the relying party identity authenticator node, so that the relying party qualification certifier node performs relying party identity authentication.
7 . The method according to claim 2 , wherein the relying party qualification certifier node comprises a security credential authenticator node;
the relying party qualification information comprises a relying party security credential and an identifier of a security credential authenticator node that issues the relying party security credential; and the transmitting the relying party qualification information to the relying party qualification certifier node, so that the relying party qualification certifier node performs relying party qualification authentication comprises: transmitting the relying party security credential to the security credential authenticator node corresponding to the identifier of the security credential authenticator node, so that the relying party qualification certifier node performs relying party security credential authentication.
8 . The method according to claim 1 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
searching a correspondence table of identity authentication assurance levels, services, and user identity credentials, to determine user identity credentials that match the identity authentication assurance level and the service provided by the relying party; presenting the determined user identity credentials as candidate user identity credentials to the user of the service; and determining one of the candidate user identity credentials selected by the user of the service as the user identity credential used by the user for the service.
9 . A computer device acting as a personal security kernel node of an identity authentication system to perform an identity authentication method, the identity authentication system further comprising a relying party node and a user identity credential certifier node, the computer device comprising:
a memory, storing computer-readable instructions; and a processor, configured to execute the computer-readable instructions stored in the memory, to perform a plurality of operations including: obtaining an identity authentication assurance level corresponding to a service provided by a relying party; determining, according to the identity authentication assurance level, a user identity credential used by a user for the service; in accordance with a determination that the user identity credential is a legal identity credential, transmitting the user identity credential to the legal user identity credential certifier node via the relying party node, wherein the legal user identity credential certifier node is configured to perform user identity credential authentication for the user for the service; in accordance with a determination that the user identity credential is a service-level user identity credential, transmitting the user identity credential to the service-level user identity credential certifier node via the relying party node, wherein the service-level user identity credential certifier node is configured to perform user identity credential authentication for the user for the service; and performing the service with the relying party node in response to reception of a receipt indicating that the user identity credential authentication succeeds from one of the legal user identity credential certifier node and the service-level user identity credential certifier node.
10 . The computer device according to claim 9 , wherein the identity authentication system further comprises a relying party qualification certifier node, and the method further comprises:
obtaining relying party qualification information; and transmitting the relying party qualification information to the relying party qualification certifier node, wherein the relying party qualification certifier node performs relying party qualification authentication; and the obtaining an identity authentication assurance level corresponding to a service provided by a relying party comprises: obtaining, in response to receiving a reply indicating that the relying party qualification authentication succeeds from the relying party qualification certifier node, the identity authentication assurance level corresponding to the service provided by the relying party.
11 . The computer device according to claim 9 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
presenting candidate user identity credentials that match the identity authentication assurance level and the service provided by the relying party; and receiving a candidate user identity credential selected by the user, and determining the candidate user identity credential selected by the user as the user identity credential used by the user for the service.
12 . The computer device according to claim 11 , wherein the identity authentication system further comprises a peer certifier node, and after the obtaining an identity authentication assurance level corresponding to a service provided by a relying party, the method further comprises:
presenting peer certifier identifiers that match the identity authentication assurance level and the service provided by the relying party; receiving a peer certifier identifier selected by the user, and using the selected peer certifier identifier as authorization of the user to a peer certifier corresponding to the peer certifier identifier; transmitting the peer certifier identifier selected by the user to the relying party node, so that the relying party node transmits a verification request to the peer certifier corresponding to the peer certifier identifier; and performing the service with the relying party node in a case that a receipt indicating successful peer authentication transmitted by the peer certifier through the relying party node is received.
13 . The computer device according to claim 10 , wherein before the obtaining relying party qualification information, the method further comprises:
generating a pair of public and private keys of the user for the user in response to received user information, storing the private key, and issuing the public key; and after the performing the service with the relying party node, the method further comprises: signing a service performance result with the private key of the user, and transmitting the service performance result and the signature together to the relying party node, so that the relying party node verifies the signature by using the public key of the user.
14 . The computer device according to claim 10 , wherein the relying party qualification certifier node comprises a relying party identity authenticator node;
the relying party qualification information comprises a relying party identity certificate and an identifier of a relying party identity authenticator node that issues the relying party identity certificate; and the transmitting the relying party qualification information to the relying party qualification certifier node, so that the relying party qualification certifier node performs relying party qualification authentication comprises: transmitting the relying party identity certificate to the relying party identity authenticator node corresponding to the identifier of the relying party identity authenticator node, so that the relying party qualification certifier node performs relying party identity authentication.
15 . The computer device according to claim 10 , wherein the relying party qualification certifier node comprises a security credential authenticator node;
the relying party qualification information comprises a relying party security credential and an identifier of a security credential authenticator node that issues the relying party security credential; and the transmitting the relying party qualification information to the relying party qualification certifier node, so that the relying party qualification certifier node performs relying party qualification authentication comprises: transmitting the relying party security credential to the security credential authenticator node corresponding to the identifier of the security credential authenticator node, so that the relying party qualification certifier node performs relying party security credential authentication.
16 . The computer device according to claim 9 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
searching a correspondence table of identity authentication assurance levels, services, and user identity credentials, to determine user identity credentials that match the identity authentication assurance level and the service provided by the relying party; presenting the determined user identity credentials as candidate user identity credentials to the user of the service; and determining one of the candidate user identity credentials selected by the user of the service as the user identity credential used by the user for the service.
17 . A non-transitory computer readable medium, storing computer-readable instructions, the computer-readable instructions, when executed by a processor of a computer device acting as a personal security kernel node of an identity authentication system that further comprises a relying party node and a user identity credential certifier node, causing the computer device to perform a plurality of operations including:
obtaining an identity authentication assurance level corresponding to a service provided by a relying party; determining, according to the identity authentication assurance level, a user identity credential used by a user for the service; in accordance with a determination that the user identity credential is a legal identity credential, transmitting the user identity credential to the legal user identity credential certifier node via the relying party node, wherein the legal user identity credential certifier node is configured to perform user identity credential authentication for the user for the service; in accordance with a determination that the user identity credential is a service-level user identity credential, transmitting the user identity credential to the service-level user identity credential certifier node via the relying party node, wherein the service-level user identity credential certifier node is configured to perform user identity credential authentication for the user for the service; and performing the service with the relying party node in response to reception of a receipt indicating that the user identity credential authentication succeeds from one of the legal user identity credential certifier node and the service-level user identity credential certifier node.
18 . The non-transitory computer readable medium according to claim 17 , wherein the identity authentication system further comprises a relying party qualification certifier node, and the plurality of operations further comprise:
obtaining relying party qualification information; and transmitting the relying party qualification information to the relying party qualification certifier node, wherein the relying party qualification certifier node performs relying party qualification authentication; and the obtaining an identity authentication assurance level corresponding to a service provided by a relying party comprises: obtaining, in response to receiving a reply indicating that the relying party qualification authentication succeeds from the relying party qualification certifier node, the identity authentication assurance level corresponding to the service provided by the relying party.
19 . The non-transitory computer readable medium according to claim 17 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
presenting candidate user identity credentials that match the identity authentication assurance level and the service provided by the relying party; and receiving a candidate user identity credential selected by the user, and determining the candidate user identity credential selected by the user as the user identity credential used by the user for the service.
20 . The non-transitory computer readable medium according to claim 17 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
searching a correspondence table of identity authentication assurance levels, services, and user identity credentials, to determine user identity credentials that match the identity authentication assurance level and the service provided by the relying party; presenting the determined user identity credentials as candidate user identity credentials to the user of the service; and determining one of the candidate user identity credentials selected by the user of the service as the user identity credential used by the user for the service.Join the waitlist — get patent alerts
Track US2025080531A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.